What it is
enumerateDevices() lists the audio inputs, audio outputs and video inputs the browser can see. Until you grant camera or microphone permission the labels are blank and the IDs are randomised — but the kinds and counts are visible to any page.
How websites read it
const devices = await navigator.mediaDevices.enumerateDevices();
// [{ kind: "videoinput", label: "" }, { kind: "audioinput", label: "" }, ...]
// labels stay empty until a permission is granted — the counts do notThe Lab counts kinds only. A typical laptop shows one of each; a desktop often has no camera and several outputs; a phone shows two cameras.
Why it identifies you
The counts are low-entropy on their own but describe the device class, and they persist across sessions. A headset plugged in for a week is part of your fingerprint for a week.
How risk-control systems use it
Zero devices of every kind is characteristic of servers, virtual machines and headless browsers. Counts that contradict the device class (five cameras on a phone, no audio output on a laptop) are checked next, and identical counts across many accounts on one platform stand out.
Common mistakes
Leaving the empty device list of a server; the same counts on every profile; a desktop profile that claims two cameras.
Mango is accepting waitlist registrations. These capabilities describe its first release; client access opens with invitations.
How Mango Browser handles it
CustomPer-profile device counts with plausible defaults for laptops and desktops.
Check yours
Jump to this signal in your scan results.